{"id":"CVE-2025-34253","title":"D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network","summary":"D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network. A…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"dlink","product":"nuclias_connect","affected":["nuclias_connect <= 1.3.1.4"],"published":"2025-10-16","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-34253","references":[{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10472","label":"disclosure@vulncheck.com"},{"url":"https://www.dlink.com/en/for-business/nuclias/nuclias-connect","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dlink-nuclias-connect-stored-xss","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00537,"epssPercentile":0.43114,"ingestedAt":"2026-09-30T23:29:32.434Z","slug":"CVE-2025-34253","body":"## Overview\n\nD-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development.\n\n## Affected\n\n- `nuclias_connect <= 1.3.1.4`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}